🇺🇸
TPI-Abuse
2026-09-15 17:20:59
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.74.43.136 (136.43.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.43.136 (136.43.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:20:50.786451 2026] [security2:error] [pid 11594:tid 11594] [client 34.74.43.136:44598] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||okwellbeing.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "okwellbeing.com"] [uri "/z9x8c7v6b5-debug-trigger-okwellbeing.com"] [unique_id "aql-clF34uJVFtQ7A9HLqwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
dot.mg
2026-09-15 16:14:33
(2 hours ago)
Scan of vulnerable files
Web App Attack
🇪🇸
robotstxt
2026-09-15 15:51:18
(2 hours ago)
34.74.43.136 - - [15/Sep/2026:15:50:44 +0000] "GET /wp-content/cache/autoptimize/1/js/autoptimize_27 ...
show more
34.74.43.136 - - [15/Sep/2026:15:50:44 +0000] "GET /wp-content/cache/autoptimize/1/js/autoptimize_27217644f8df93aca28e7781471b8839.js HTTP/2.0" 403 165 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" "-" edge="34.74.43.136"
34.74.43.136 - - [15/Sep/2026:15:50:45 +0000] "GET /.git/HEAD HTTP/2.0" 403 5132 "https://ojo.es/.git/HEAD" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" "-" edge="34.74.43.136"
34.74.43.136 - - [15/Sep/2026:15:50:45 +0000] "GET /?30d662=b3ebe4403e.js& HTTP/2.0" 403 2 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" "-" edge="34.74.43.136"
34.74.43.136 - - [15/Sep/2026:15:50:45 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 4894 "https://ojo.es/.vite/manifest.json" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" "-" edge="34.74.43.136"
34.74.43.
...
show less
Web App Attack
🇬🇧
oja
2026-09-15 15:45:48
(3 hours ago)
Aggressive web scanner
Web App Attack
🇸🇪
vaia.cloud
2026-09-15 15:10:05
(3 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇳🇱
Alt255
2026-09-15 15:09:12
(3 hours ago)
[ti-17al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-17al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.74.43.136 - - [15/Sep/2026:17:08:00 +0200] "GET /@fs/.env?raw&url?? HTTP/2.0" 301 518 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
34.74.43.136 - - [15/Sep/2026:17:08:00 +0200] "GET /@fs/.env?import&?raw?? HTTP/2.0" 301 526 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-15 15:05:42
(3 hours ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
🇫🇷
dynamix
2026-09-15 15:00:54
(3 hours ago)
Multiple WAF Violations
Web App Attack
🇬🇧
consul.to
2026-09-15 14:48:11
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 14:40:37
(4 hours ago)
(mod_security) mod_security (id:210580) triggered by 34.74.43.136 (136.43.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210580) triggered by 34.74.43.136 (136.43.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:40:33.920845 2026] [security2:error] [pid 11049:tid 11049] [client 34.74.43.136:41462] ModSecurity: Access denied with code 403 (phase 2). Matched phrase ".ssh/id_rsa" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||ohanameetup.party|F|2"] [data "Matched Data: .ssh/id_rsa found within ARGS:filename: file:/root/.ssh/id_rsa"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "ohanameetup.party"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqlY4WbqSJX7R82o34BY1wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 14:36:03
(4 hours ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
🇳🇱
Savvii
2026-09-15 14:29:16
(4 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 14:19:07
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.74.43.136 (136.43.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.43.136 (136.43.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:19:01.738574 2026] [security2:error] [pid 4766:tid 4766] [client 34.74.43.136:36828] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||myomni.us|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "myomni.us"] [uri "/rclone.conf"] [unique_id "aqlT1ayu-A830xa1cLNiJQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
oh.mg
2026-09-15 14:12:22
(4 hours ago)
[Tue Sep 15 16:12:18.775474 2026] [security2:error] [pid 1098361:tid 1098407] [client 34.74.43.136:0 ...
show more
[Tue Sep 15 16:12:18.775474 2026] [security2:error] [pid 1098361:tid 1098407] [client 34.74.43.136:0] [client 34.74.43.136] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 40)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "us.mmn.ca"] [uri "/api"] [unique_id "aqlSQqVmvW9UnYv_5BYdaQAAARE"]
[Tue Sep 15 16:12:21.855921 2026] [security2:error] [pid 1098361:tid 1098413] [client 34.74.43.136:0] [client 34.74.43.136] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluati
...
show less
Web App Attack
Bad Web Bot
Anonymous
2026-09-15 13:31:22
(5 hours ago)
Observed scanned 1 known-sensitive endpoint(s), e.g.: /@fs/home/ubuntu/.aws/credentials?raw??
Bad Web Bot
Web App Attack